Google pauses open source bug bounty program as AI-generated reports pile up

Google / Wikimedia Commons (Public domain)

Google pauses open source bug bounty program as AI-generated reports pile up

The company is suspending new product vulnerability submissions to its OSS VRP, citing a flood of low-quality automated reports that swamped human reviewers

Google has hit pause on part of its Open Source Software Vulnerability Reward Program. The reason is a flood of AI-generated bug reports.

Starting October 1, 2026, the company is no longer accepting new product vulnerability submissions to the program, known as the OSS VRP.

What Google is changing

Google tied the suspension to a surge of low-quality, automated reports produced with AI tools. Those reports have been landing on security engineers and on the maintainers of open source projects.

According to Google, many of these submissions contained hallucinations. Others described issues with negligible real-world impact.

Most of the submissions in this surge turned out to be invalid. That is a problem because bug bounty programs rely on manual triage. A human has to read each report, try to reproduce the issue, and decide whether it is a real vulnerability.

Advertisement

The pause is not a full shutdown. Here is how the cutoff works:

  • Reports filed before October 1 will continue to be processed without interruption.
  • Supply chain reports are not affected by the suspension.
  • Certain Cloud-related submissions can still be sent through Google’s Cloud VRP.

Google is also pointing researchers toward its other active reward programs while the OSS VRP pause is in place. It specifically mentioned its Patch Rewards program as an option.

The company says it plans to revise how submissions work. A formal update on those reforms is expected in Q1 2027.

A problem Google already tried to fix

This is not Google’s first attempt to manage the problem. In March 2026, the company adjusted its VRP criteria to slow the flow of low-quality reports. The changes raised the bar on the evidence researchers needed to provide.

Google also made changes to its reward programs for Android and Chrome during 2026. The OSS VRP suspension is the most aggressive step so far.

Google is far from alone. The Internet Bug Bounty program has run into the same issue. So have Intel and the maintainers of the Linux kernel, who have all dealt with rising volumes of questionable reports driven by generative AI.

Some of those programs have responded with pauses and adjustments of their own.

Why the bounty model is under strain

Open source projects feel this most acutely. Many are maintained by small teams or volunteers who have no spare capacity to debunk hallucinated vulnerabilities. Google cited the burden on these maintainers directly in explaining the pause.

What this means

For security researchers, the immediate effect is a narrower set of places to earn rewards from Google’s open source work. Legitimate researchers who find real flaws in open source products will need to look at other Google VRPs or the Patch Rewards program.

The Q1 2027 update is the next marker to track. It will show whether Google believes the bounty model can be repaired with better rules, or whether open source security rewards need a different structure entirely.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.
Google pauses open source bug bounty program as AI-generated reports pile up
Google pauses open source bug bounty program as AI-generated reports pile up

The company is suspending new product vulnerability submissions to its OSS VRP, citing a flood of low-quality automated reports that swamped human reviewers

Google / Wikimedia Commons (Public domain)

Google has hit pause on part of its Open Source Software Vulnerability Reward Program. The reason is a flood of AI-generated bug reports.

Starting October 1, 2026, the company is no longer accepting new product vulnerability submissions to the program, known as the OSS VRP.

What Google is changing

Google tied the suspension to a surge of low-quality, automated reports produced with AI tools. Those reports have been landing on security engineers and on the maintainers of open source projects.

According to Google, many of these submissions contained hallucinations. Others described issues with negligible real-world impact.

Most of the submissions in this surge turned out to be invalid. That is a problem because bug bounty programs rely on manual triage. A human has to read each report, try to reproduce the issue, and decide whether it is a real vulnerability.

Advertisement

The pause is not a full shutdown. Here is how the cutoff works:

  • Reports filed before October 1 will continue to be processed without interruption.
  • Supply chain reports are not affected by the suspension.
  • Certain Cloud-related submissions can still be sent through Google’s Cloud VRP.

Google is also pointing researchers toward its other active reward programs while the OSS VRP pause is in place. It specifically mentioned its Patch Rewards program as an option.

The company says it plans to revise how submissions work. A formal update on those reforms is expected in Q1 2027.

A problem Google already tried to fix

This is not Google’s first attempt to manage the problem. In March 2026, the company adjusted its VRP criteria to slow the flow of low-quality reports. The changes raised the bar on the evidence researchers needed to provide.

Google also made changes to its reward programs for Android and Chrome during 2026. The OSS VRP suspension is the most aggressive step so far.

Google is far from alone. The Internet Bug Bounty program has run into the same issue. So have Intel and the maintainers of the Linux kernel, who have all dealt with rising volumes of questionable reports driven by generative AI.

Some of those programs have responded with pauses and adjustments of their own.

Why the bounty model is under strain

Open source projects feel this most acutely. Many are maintained by small teams or volunteers who have no spare capacity to debunk hallucinated vulnerabilities. Google cited the burden on these maintainers directly in explaining the pause.

What this means

For security researchers, the immediate effect is a narrower set of places to earn rewards from Google’s open source work. Legitimate researchers who find real flaws in open source products will need to look at other Google VRPs or the Patch Rewards program.

The Q1 2027 update is the next marker to track. It will show whether Google believes the bounty model can be repaired with better rules, or whether open source security rewards need a different structure entirely.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.